Missing Authentication in Hugging Face LeRobot Component
CVE-2025-10772
What is CVE-2025-10772?
A vulnerability has been identified in the Hugging Face LeRobot software, specifically within the ZeroMQ Socket Handler component located at lerobot/common/robot_devices/robots/lekiwi_remote.py. This issue arises from a missing authentication mechanism, enabling unauthorized access to functionality when operated within a local network environment. Although the vendor was notified of this vulnerability, they have not provided any response or remediation, posing a potential risk to users operating this software version.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
LeRobot 0.3.0
LeRobot 0.3.1
LeRobot 0.3.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
